What are the responsibilities and job description for the Azure Cloud Security Engineer position at New Millenium Consulting?
Job Title: Azure Cloud Security Engineer
Job Type: Full-time
Job Location: Fort Washington, PA (Flexible 1-2 days onsite)
A leading healthcare is seeking an Azure Cloud Security Engineer to join the security team. The Azure GRC Expert will be accountable for spearheading the organization's cloud governance and security posture management across the Azure and Microsoft 365 environment, ensuring sustained compliance with the organization's cloud security benchmark and the continuous reduction of cloud-based risk
Ideally, the Azure Cloud Security Engineer will have experience with:
- Azure Policy & Policy as Code
- Azure Engineering - Intermediate knowledge (Resources, Best Practices, Infrastructure as Code, Architecture basics
- Azure Resource Remediation - Via policy changes or infrastructure modules like ARM or Terraform
- AI Architecture -Conceptual knowledge with how custom AI solutions should be built securely.
Azure Cloud Security Engineer owns the design and ongoing maintenance of cloud-relevant policies, standards, and configuration baselines, and partners with cloud engineering to enforce secure configurations, remediate posture findings, and validate corrective actions. Provides targeted oversight of cloud-focused risk assessments, advises on governance priorities, and reports on cloud compliance and posture progress to leadership, advancing the organization's overall information security and compliance posture.
ESSENTIAL FUNCTIONS
- Provide strategic vision and roadmap for cloud governance and compliance across the Azure and Microsoft 365 environment, aligning cloud GRC activities with organizational objectives and regulatory requirements.
- Design and continually enhance cloud-related information security policies, standards, and configuration baselines, including processes to manage and document exceptions.
- Provide oversight of targeted risk assessments that support cloud governance and compliance objectives, synthesizing findings to inform leadership on cloud security posture and emerging cloud-based risks.
- Spearhead cloud governance and security posture management across the Azure and Microsoft 365 environment, ensuring sustained compliance with the organization's cloud security benchmark and recommending control settings to restrict insecure configurations.
- Partner with cloud engineering to remediate posture findings, validate corrective actions, and report on remediation progress and overall cloud security posture to leadership.
- Collaborate with cross-functional teams, particularly cloud engineering, to integrate cloud governance, security, and compliance requirements into operational policies, processes, and platform standards.
- Mentor and coach GRC analysts supporting cloud governance and compliance activities, fostering operational excellence and professional growth.
- Develop dashboards and data pipelines to measure and communicate cloud compliance, posture progress, and related governance metrics to senior stakeholders